CVE-2026-1937Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-18); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-18: 4Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-18: 4Technical Details · 2026-02-27: 102-1802-27
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-184
Disclosure3Patch1
2026-02-271
Patch1
Full discourse5 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical #WooCommerce plugin privilege escalation (CVE-2026-1937)! The YayMail – WooCommerce Email Customizer plugin (≤ 4.3.2) has a missing capability check on the yaymail_import_state AJAX action, allowing authenticated users (Shop Manager+) to modify arbitrary options — including elevating privileges or creating admin users. 🔓 If you use this plugin on your e-commerce site, attackers could shift roles and take over your store without proper checks. 🛠 Mitigation: Update or remove the plugin now, and then run a full scan for malware/backdoors. Cleanup → https://quttera.com/remove-malware-from-website #WooCommerce #WordPress #CVE20261937 #WebSecurity #Infosec #ThreatIntel #CVE #Malware

    Post summary

    The post announces a privilege‑escalation flaw in the YayMail WooCommerce Email Customizer plugin (CVE‑2026‑1937) and urges users to update or remove the plugin, highlighting the missing capability check that enables attackers to create admin accounts.

    1000032
    37 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1937 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missin… https://www.cve.org/CVERecord?id=CVE-2026-1937

    Post summary

    The YayMail WooCommerce Email Customizer plugin is vulnerable to unauthorized data modification that can lead to privilege escalation, as identified in CVE‑2026‑1937.

    00000193
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Vulnerability in YayMail – WooCommerce Email Customizer lets attackers escalate privileges via missing authorization! All versions impacted. Patch ASAP! https://radar.offseq.com/threat/cve-2026-1937-cwe-862-missing-authorization-in-yay-12c0a139 #OffSeq #WordPress #... https://t.co/q6cWb22YWN

    Post summary

    A critical missing‑authorization flaw in YayMail (CVE‑2026‑1937) affects all versions and requires an immediate patch, with no evidence of active exploitation or PoC provided.

    0000037
    265 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1937 - Critical The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check... https://www.thehackerwire.com/vulnerability/CVE-2026-1937/ https://t.co/p5KbxZ84jW

    Post summary

    CVE-2026-1937 is a critical flaw in the YayMail WooCommerce Email Customizer plugin, enabling privilege escalation via missing capability checks; no PoC, exploit tool, patch, or active exploitation information is provided.

    0000051
    112 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1937: YayMail <= 4.3.2 - Missing Author... Shop Manager to Admin in one AJAX call: YayMail's unprotected 'yaymail_import_state' lets attackers update any option, i... https://zerodaysignal.com/vulnerability/CVE-2026-1937 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑1937 for YayMail <=4.3.2, detailing an unprotected AJAX endpoint that permits attackers to elevate privileges by updating options, but provides no PoC, exploit code, or patch information.

    0000059
    131 followersView on X

Explore more